Good luck getting that through Capitol Hill. The Republicans are scum ofcourse but its not like the Democrats don't get funding from vested business interests...
Brendan Eich Writes to the US Senate: We Need a GDPR for the United States
231–238 of 238 posts
Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States
#232Earlier quoted context omitted.
>"What we wish is to be able to opt-in once and for all, to get rid of these incessant interstitial pop-ups sprouting like mushrooms across the Internet." If they implemented GDPR correctly and in a sensible manner, you would get one popup per site, once. You would give your consent to data collection and usage, and they would save that preference in a cookie or your profile settings for that site. Instead, they want…
> If they implemented GDPR correctly and in a sensible manner, you would get one popup per site, once. You would give your consent to data collection and usage, and they would save that preference in a cookie or your profile settings for that site. And how is that supposed to work, exactly? If you choose "deny" then they can't track you, so they can't set a cookie or save profile data! Of course you'll get the same p…
Abolish the popups entirely, move the consent forms to a voluntary options page. Implement a user profile system, so people can create a profile and opt-in to tracking and profiling through that. Turn off tracking and profiling completely for anonymous users who choose not to create a profile, or who haven't opted in.
I know there will be an outcry of "but the amount of data we would be able to gather is miniscule!", and I say that's a good thing. Companies have absolutely no right to my personal data and to infringe on my privacy, unless I explicitly grant them access to do so.
The default should be to not track and not profile and not store privacy-infringing data, unless the user has taken specific and deliberate action to allow it.
>"There is nothing "onerous" about their terms. They have every right to require your consent in exchange for their services, the GDPR's infringement of that right notwithstanding."
They have absolutely no right to my private data, unless I specifically give them permission. They do not have any right to success, no right to a specific business model being viable forever.
>"For that matter, they have every right to collect, store, and make use of whatever data they are able to gather from your interaction with their service without your consent. The law in this case is blatantly one-sided, and consequently unjust—you aren't forced to beg for their consent to remember and/or communicate whatever data you can gather about the them."
No, they do not have that right. There are very clear differences between corporations and people. Corps are not people, they do not have the same rights a person does.
>"For that matter, where is the GDPR equivalent for the government? They collect more information, and more personal information, than anyone else. Based on the same principles as the GDPR, you should be able to opt out of all those income and sales tax reporting forms, for a start, or demand that they delete you from all their databases, with no change in services received."
The GDPR applies to governments as well. There are very specific rules in place for what information they're allowed to keep, any PII data can only be kept if there is valid purpose. The same rules go for companies, they're certainly allowed to keep information, as long as it's appropriate and necessary to provide the services they provide to you. And yes, taxation is part of the overall service government provides you to, specifically it's the payment for those services.
Facebook doesn't need to endlessly track, profile and monetize you, in order to run a social network that lets you chat with people, exchange cat videos and arrange events. Google doesn't need to endlessly track, profile and monetize you in order to provide search, email, calendars and their other services. It's perfectly fine to keep your calendar data, because that's a service they provide to you. But it is not OK for them to analyze and monetize your calendar data to target ads, unless you give them explicit consent.
Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States
#233Earlier quoted context omitted.
I agree that these are real negative effects of GDPR. However, the concrete design of these pop-ups is mostly not GDPR-compliant: for example, users not agreeing to being tracked must not be disadvantaged, and having to click through a cumbersome array of options is certainly a disadvantage. At least for European web sites, the authorities will hopefully take action after a while, and then these bad practices will st…
I don’t get the disadvantage comment: everyone gets the popup crap, whether you say no or yes. Maybe I visit different sites, maybe I don’t notice because I reflexively click the closest button? In any case, the disadvantaging language is hardly meant that way: it’s about withdrawing actual content or features from you. We have waited a few years with cookies law and nothing changed. Unless some browser based fix tak…
The jury is still out, but it is only a few months since GDPR is in place.
Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States
#234Earlier quoted context omitted.
>By assuming they will, and taking steps to not provide your data to all and sundry. At the end of the day, companies can sell your data because they have it. Okay I now assume that all companies will harvest as much data as they can. I will now take steps to prevent this. I am now offline and there is no way to know if they do.
> Okay I now assume that all companies will harvest as much data as they can. You say harvest, as if they are taking something. The reality is, people always gave the data. The companies just kept what it was freely given. It's a bit hypocritical if I get upset that you keep something I gave you. The reality is, the problem wasn't with the users who gave the data, or the companies who kept what was given, but rather…
Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States
#235Earlier quoted context omitted.
While I haven't listened to your linked episode, 'privacy laws' by definition come into direct conflict with the 1st amendment (i.e. free speech) to the U.S Constitution.
I admit I'm not an American citizen, and have never actually stepped foot on American soil, but I do see the "first amendment" and "free speech" arguments being trotted out for almost anything that involves communication between two parties being restricted. This, in my experience has been common in (privately owned) web forums when an American user is banned for misbehaviour, or rules are changed to prohibit certain…
The EU (you might be surprised to learn) also recognises the freedom of speech (in fact it's a universal human right, see [2] article 19). However, this does not mean GDPR is not valid law, just as I have a hard time understanding how the first amendment would prohibit privacy laws to exist.
[1] https://en.wikipedia.org/wiki/United_States_free_speech_exce...
[2] http://www.un.org/en/universal-declaration-human-rights/
Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States
#236Earlier quoted context omitted.
> If they implemented GDPR correctly and in a sensible manner, you would get one popup per site, once. You would give your consent to data collection and usage, and they would save that preference in a cookie or your profile settings for that site. And how is that supposed to work, exactly? If you choose "deny" then they can't track you, so they can't set a cookie or save profile data! Of course you'll get the same p…
>"And how is that supposed to work, exactly?" Abolish the popups entirely, move the consent forms to a voluntary options page. Implement a user profile system, so people can create a profile and opt-in to tracking and profiling through that. Turn off tracking and profiling completely for anonymous users who choose not to create a profile, or who haven't opted in. I know there will be an outcry of "but the amount of d…
Services you personally asked them to provide to you. That's an entirely different standard. The GDPR doesn't permit companies to decide unilaterally what services they will provide and what information (much less funds) they are entitled to collect from you in order to provide those unasked-for services.
Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States
#237Earlier quoted context omitted.
What material harm or damage would you suffer if I snooped on all of your Internet browsing activity with the knowledge of who you are in real life and kept that information around forever to use for whatever purposes I so choose?
Straw man. That’s not analogous to what was being discussed. A better analogy is: HN can see my email because I gave it to them to login. I don’t need to request what HN is doing with my email, because I already know I gave it to them. Giving them my email doesn’t harm me. Using it to do something illegal might, but the GDPR wouldn’t be able to stop that.
Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States
#238Earlier quoted context omitted.
> You don't have to do anything .... just email the website ... Okay ... let me try this. > TO: cnn.com > SUBJECT: Remove my data Okay, let's send it! > gmail: The address "cnn.com" in the "To" field was not recognized. Please make sure that all addresses are properly formed. Oh. I've been around the block; maybe I can try admin@ or support@ or look at whois data, or browse around their website for a "Contact us" lin…
https://opt-out.eu/ is a service run by AFAIR someone on HN (spotted it today, can't find the source comment). Select a company, fill out a form, and you're done[0]. This is the template they seem to be using for erasure requests: https://github.com/opt-out-eu/opt-out/blob/master/src/email-... . -- [0] - Maybe. I'm not endorsing it, I just found it today. I wish someone (maybe the author) could say something more abo…